Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
G.rodola pyftpdlib PASV命令相关端口设计错误
Vulnerability Description
pyftpdlib(Python FTP server library)提供了高级的可移植的编程接口,用来实现异步的FTP服务器的功能。 pyftpdlib 0.1.1之前版本中不能为与PASV命令相关联的端口选择随机值。远程攻击者更容易借助读取该命令的响应获取有关in-progress数据连接数目的潜在敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A